init.c 11.0 KB
Newer Older
1
/*
X
xionglei6 已提交
2
 * Copyright (c) 2021 Huawei Device Co., Ltd.
3 4 5 6 7 8 9 10 11 12 13 14 15 16 17
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 * http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */
#include "init.h"

#include <errno.h>
X
xionglei6 已提交
18
#include <poll.h>
19 20 21 22 23
#include <stdlib.h>
#include <signal.h>
#include <sys/sysmacros.h>
#include <sys/stat.h>
#include <sys/types.h>
X
xionglei6 已提交
24
#include <sys/socket.h>
4
411148299@qq.com 已提交
25
#include <linux/major.h>
26
#include "device.h"
X
xionglei6 已提交
27
#include "fd_holder_service.h"
X
xionglei6 已提交
28
#include "fs_manager/fs_manager.h"
29 30
#include "init_log.h"
#include "init_mount.h"
X
xionglei6 已提交
31
#include "init_group_manager.h"
32
#include "init_param.h"
X
xionglei6 已提交
33 34
#include "init_service.h"
#include "init_service_manager.h"
35 36 37
#include "init_utils.h"
#include "securec.h"
#include "switch_root.h"
X
xionglei6 已提交
38 39
#include "ueventd.h"
#include "ueventd_socket.h"
X
xionglei6 已提交
40
#include "fd_holder_internal.h"
X
xionglei6 已提交
41 42
#include "sandbox.h"
#include "sandbox_namespace.h"
Q
Qin Fandong 已提交
43
#ifdef WITH_SELINUX
X
xionglei6 已提交
44
#include <policycoreutils.h>
R
renwei 已提交
45
#include <selinux/selinux.h>
Q
Qin Fandong 已提交
46
#endif // WITH_SELINUX
47

X
xionglei6 已提交
48 49
static bool g_enableSandbox;

X
xionglei6 已提交
50 51 52 53
static int FdHolderSockInit(void)
{
    int sock = -1;
    int on = 1;
X
xionglei6 已提交
54 55
    int fdHolderBufferSize = FD_HOLDER_BUFFER_SIZE; // 4KiB
    sock = socket(AF_UNIX, SOCK_DGRAM | SOCK_CLOEXEC | SOCK_NONBLOCK, 0);
X
xionglei6 已提交
56 57 58 59 60 61 62 63 64 65 66 67 68
    if (sock < 0) {
        INIT_LOGE("Failed to create fd holder socket, err = %d", errno);
        return -1;
    }

    setsockopt(sock, SOL_SOCKET, SO_RCVBUFFORCE, &fdHolderBufferSize, sizeof(fdHolderBufferSize));
    setsockopt(sock, SOL_SOCKET, SO_PASSCRED, &on, sizeof(on));

    if (access(INIT_HOLDER_SOCKET_PATH, F_OK) == 0) {
        INIT_LOGI("%s exist, remove it", INIT_HOLDER_SOCKET_PATH);
        unlink(INIT_HOLDER_SOCKET_PATH);
    }
    struct sockaddr_un addr;
X
xionglei6 已提交
69
    addr.sun_family = AF_UNIX;
X
xionglei6 已提交
70 71 72 73 74 75 76 77
    if (strncpy_s(addr.sun_path, sizeof(addr.sun_path),
        INIT_HOLDER_SOCKET_PATH, strlen(INIT_HOLDER_SOCKET_PATH)) != 0) {
        INIT_LOGE("Faild to copy fd hoder socket path");
        close(sock);
        return -1;
    }
    socklen_t len = (socklen_t)(offsetof(struct sockaddr_un, sun_path) + strlen(addr.sun_path) + 1);
    if (bind(sock, (struct sockaddr *)&addr, len) < 0) {
X
xionglei6 已提交
78
        INIT_LOGE("Failed to binder fd folder socket %d", errno);
X
xionglei6 已提交
79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94
        close(sock);
        return -1;
    }

    // Owned by root
    if (lchown(addr.sun_path, 0, 0)) {
        INIT_LOGW("Failed to change owner of fd holder socket, err = %d", errno);
    }
    mode_t mode = S_IRUSR | S_IWUSR | S_IRGRP | S_IWGRP | S_IROTH | S_IWOTH;
    if (fchmodat(AT_FDCWD, addr.sun_path, mode, AT_SYMLINK_NOFOLLOW)) {
        INIT_LOGW("Failed to change mode of fd holder socket, err = %d", errno);
    }
    INIT_LOGI("Init fd holder socket done");
    return sock;
}

95 96 97
void SystemInit(void)
{
    SignalInit();
X
xionglei6 已提交
98 99
    // umask call always succeeds and return the previous mask value which is not needed here
    (void)umask(DEFAULT_UMASK_INIT);
100
    MakeDirRecursive("/dev/unix/socket", S_IRWXU | S_IRGRP | S_IXGRP | S_IROTH | S_IXOTH);
X
xionglei6 已提交
101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118
    int sock = FdHolderSockInit();
    if (sock >= 0) {
        RegisterFdHoldWatcher(sock);
    }
}

static void EnableDevKmsg(void)
{
    /* printk_devkmsg default value is ratelimit, We need to set "on" and remove the restrictions */
    int fd = open("/proc/sys/kernel/printk_devkmsg", O_WRONLY | O_CLOEXEC, S_IRUSR | S_IWUSR | S_IRGRP | S_IRGRP);
    if (fd < 0) {
        return;
    }
    char *kmsgStatus = "on";
    write(fd, kmsgStatus, strlen(kmsgStatus) + 1);
    close(fd);
    fd = -1;
    return;
119 120 121 122 123 124 125 126 127 128 129 130
}

void LogInit(void)
{
    CloseStdio();
    int ret = mknod("/dev/kmsg", S_IFCHR | S_IWUSR | S_IRUSR,
        makedev(MEM_MAJOR, DEV_KMSG_MINOR));
    if (ret == 0) {
        OpenLogDevice();
    }
}

X
xionglei6 已提交
131
static char **GetRequiredDevices(Fstab fstab, int *requiredNum)
132
{
X
xionglei6 已提交
133 134 135 136 137 138 139
    int num = 0;
    FstabItem *item = fstab.head;
    while (item != NULL) {
        if (FM_MANAGER_REQUIRED_ENABLED(item->fsManagerFlags)) {
            num++;
        }
        item = item->next;
140
    }
X
xionglei6 已提交
141 142 143 144 145 146 147 148 149 150 151
    char **devices = (char **)calloc(num, sizeof(char *));
    INIT_ERROR_CHECK(devices != NULL, return NULL, "Failed calloc err=%d", errno);

    int i = 0;
    item = fstab.head;
    while (item != NULL) {
        if (FM_MANAGER_REQUIRED_ENABLED(item->fsManagerFlags)) {
            devices[i] = strdup(item->deviceName);
            INIT_ERROR_CHECK(devices[i] != NULL, FreeStringVector(devices, num); return NULL,
                "Failed strdup err=%d", errno);
            i++;
152
        }
X
xionglei6 已提交
153
        item = item->next;
154
    }
X
xionglei6 已提交
155 156
    *requiredNum = num;
    return devices;
157 158
}

X
xionglei6 已提交
159
static int StartUeventd(char **requiredDevices, int num)
160
{
X
xionglei6 已提交
161 162 163 164 165
    INIT_ERROR_CHECK(requiredDevices != NULL && num > 0, return -1, "Failed parameters");
    int ueventSockFd = UeventdSocketInit();
    if (ueventSockFd < 0) {
        INIT_LOGE("Failed to create uevent socket");
        return -1;
166
    }
X
xionglei6 已提交
167
    RetriggerUevent(ueventSockFd, requiredDevices, num);
X
xionglei6 已提交
168
    close(ueventSockFd);
X
xionglei6 已提交
169 170 171 172 173 174 175
    return 0;
}

static void StartInitSecondStage(void)
{
    const char *fstabFile = "/etc/fstab.required";
    Fstab *fstab = NULL;
X
xionglei6 已提交
176 177 178
    if (access(fstabFile, F_OK) != 0) {
        fstabFile = "/system/etc/fstab.required";
    }
X
xionglei6 已提交
179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197
    INIT_ERROR_CHECK(access(fstabFile, F_OK) == 0, abort(), "Failed get fstab.required");
    fstab = ReadFstabFromFile(fstabFile, false);
    INIT_ERROR_CHECK(fstab != NULL, abort(), "Read fstab file \" %s \" failed\n", fstabFile);

    int requiredNum = 0;
    char **devices = GetRequiredDevices(*fstab, &requiredNum);
    if (devices != NULL && requiredNum > 0) {
        int ret = StartUeventd(devices, requiredNum);
        if (ret == 0) {
            ret = MountRequriedPartitions(fstab);
        }
        FreeStringVector(devices, requiredNum);
        devices = NULL;
        ReleaseFstab(fstab);
        fstab = NULL;
        if (ret < 0) {
            // If mount required partitions failure.
            // There is no necessary to continue.
            // Just abort
X
xionglei6 已提交
198 199 200
            INIT_LOGE("Mount requried partitions failed; please check fstab file");
            // Execute sh for debugging
            execv("/bin/sh", NULL);
X
xionglei6 已提交
201 202
            abort();
        }
203
    }
X
xionglei6 已提交
204
#ifndef DISABLE_INIT_TWO_STAGES
205 206
    SwitchRoot("/usr");
    // Execute init second stage
X
xionglei6 已提交
207
    char * const args[] = {
208 209
        "/bin/init",
        "--second-stage",
S
sun_fan 已提交
210
        NULL,
211 212 213 214 215
    };
    if (execv("/bin/init", args) != 0) {
        INIT_LOGE("Failed to exec \"/bin/init\", err = %d", errno);
        exit(-1);
    }
S
sun_fan 已提交
216
#endif
X
xionglei6 已提交
217
}
218 219 220 221

void SystemPrepare(void)
{
    MountBasicFs();
X
xionglei6 已提交
222
    LogInit();
223 224 225 226 227 228
    // Make sure init log always output to /dev/kmsg.
    EnableDevKmsg();
    CreateDeviceNode();
    // Only ohos normal system support
    // two stages of init.
    // If we are in updater mode, only one stage of init,
S
sun_fan 已提交
229
    INIT_LOGI("DISABLE_INIT_TWO_STAGES not defined");
230 231 232 233 234
    if (InUpdaterMode() == 0) {
        StartInitSecondStage();
    }
}

Q
Qin Fandong 已提交
235 236 237 238
void SystemLoadSelinux(void)
{
#ifdef WITH_SELINUX
    // load selinux policy and context
R
renwei 已提交
239
    if (LoadPolicy() < 0) {
Q
Qin Fandong 已提交
240 241 242 243
        INIT_LOGE("main, load_policy failed.");
    } else {
        INIT_LOGI("main, load_policy success.");
    }
R
renwei 已提交
244 245

    setcon("u:r:init:s0");
R
renwei 已提交
246
    (void)RestoreconRecurse("/dev");
Q
Qin Fandong 已提交
247 248 249
#endif // WITH_SELINUX
}

X
xionglei6 已提交
250 251 252 253
static void BootStateChange(const char *content)
{
    INIT_LOGI("boot start %s finish.", content);
    if (strcmp("init", content) == 0) {
X
xionglei6 已提交
254
        StartAllServices(START_MODE_BOOT);
X
xionglei6 已提交
255 256 257 258 259 260 261 262 263
        return;
    }
    if (strcmp("post-init", content) == 0) {
        StartAllServices(START_MODE_NARMAL);
        return;
    }
}

#if defined(OHOS_SERVICE_DUMP)
X
xionglei6 已提交
264
static int SystemDump(int id, const char *name, int argc, const char **argv)
X
xionglei6 已提交
265
{
X
xionglei6 已提交
266
    INIT_ERROR_CHECK(argv != NULL && argc >= 1, return 0, "Invalid install parameter");
X
xionglei6 已提交
267 268 269
    INIT_LOGI("Dump system info %s", argv[0]);
    DumpAllServices();
    DumpParametersAndTriggers();
X
xionglei6 已提交
270
    return 0;
X
xionglei6 已提交
271 272 273
}
#endif

X
xionglei6 已提交
274 275 276 277 278 279 280 281 282 283
static void IsEnableSandbox(void)
{
    const char *name = "const.sandbox";
    char value[MAX_BUFFER_LEN] = {0};
    unsigned int len = MAX_BUFFER_LEN;
    if (SystemReadParam(name, value, &len) != 0) {
        INIT_LOGE("Failed read param.");
        g_enableSandbox = false;
    }
    if (strcmp(value, "enable") == 0) {
X
xionglei6 已提交
284
        INIT_LOGI("Enable sandbox.");
X
xionglei6 已提交
285 286
        g_enableSandbox = true;
    } else {
X
xionglei6 已提交
287
        INIT_LOGI("Disable sandbox.");
X
xionglei6 已提交
288 289 290 291
        g_enableSandbox = false;
    }
}

292 293
void SystemConfig(void)
{
X
xionglei6 已提交
294 295 296
    InitServiceSpace();
    InitParseGroupCfg();
    PluginManagerInit();
R
renwei 已提交
297

298
    InitParamService();
X
xionglei6 已提交
299 300
    RegisterBootStateChange(BootStateChange);

R
renwei 已提交
301 302 303 304
    // load SELinux context and policy
    // Do not move position!
    SystemLoadSelinux();

305 306 307 308 309 310 311 312 313
    // parse parameters
    LoadDefaultParams("/system/etc/param/ohos_const", LOAD_PARAM_NORMAL);
    LoadDefaultParams("/vendor/etc/param", LOAD_PARAM_NORMAL);
    LoadDefaultParams("/system/etc/param", LOAD_PARAM_ONLY_ADD);
    // read config
    ReadConfig();
    INIT_LOGI("Parse init config file done.");

    // dump config
X
xionglei6 已提交
314 315 316
#if defined(OHOS_SERVICE_DUMP)
    AddCmdExecutor("display", SystemDump);
    (void)AddCompleteJob("param:ohos.servicectrl.display", "ohos.servicectrl.display=*", "display system");
317
#endif
X
xionglei6 已提交
318
    IsEnableSandbox();
319 320 321 322 323 324 325 326 327 328
    // execute init
    PostTrigger(EVENT_TRIGGER_BOOT, "pre-init", strlen("pre-init"));
    PostTrigger(EVENT_TRIGGER_BOOT, "init", strlen("init"));
    PostTrigger(EVENT_TRIGGER_BOOT, "post-init", strlen("post-init"));
}

void SystemRun(void)
{
    StartParamService();
}
X
xionglei6 已提交
329

X
xionglei6 已提交
330
void SetServiceEnterSandbox(const char *execPath, unsigned int attribute)
X
xionglei6 已提交
331 332
{
    if (g_enableSandbox == false) {
X
xionglei6 已提交
333
        return;
X
xionglei6 已提交
334
    }
X
xionglei6 已提交
335 336 337 338 339 340 341 342 343
    if ((attribute & SERVICE_ATTR_SANDBOX) != SERVICE_ATTR_SANDBOX) {
        return;
    }
    INIT_ERROR_CHECK(execPath != NULL, return, "Service path is null.");
    if (strncmp(execPath, "/system/bin/", strlen("/system/bin/")) == 0) {
        if (strcmp(execPath, "/system/bin/appspawn") == 0) {
            INIT_LOGI("Appspawn skip enter sandbox.");
        } else if (strcmp(execPath, "/system/bin/hilogd") == 0) {
            INIT_LOGI("Hilogd skip enter sandbox.");
X
xionglei6 已提交
344
        } else {
X
xionglei6 已提交
345 346
            INIT_ERROR_CHECK(EnterSandbox("system") == 0, return,
                "Service %s failed enter sandbox system.", execPath);
X
xionglei6 已提交
347
        }
X
xionglei6 已提交
348 349 350 351
    } else if (strncmp(execPath, "/vendor/bin/", strlen("/vendor/bin/")) == 0) {
        // chipset sandbox will be implemented later.
        INIT_ERROR_CHECK(EnterSandbox("system") == 0, return,
            "Service %s failed enter sandbox system.", execPath);
X
xionglei6 已提交
352
    } else {
X
xionglei6 已提交
353
        INIT_LOGE("Service %s does not enter sandbox", execPath);
X
xionglei6 已提交
354
    }
X
xionglei6 已提交
355
    return;
X
xionglei6 已提交
356
}